Jump to content

object is infected by HEUR:Trojan.Script.Balada.gen

Go to solution Solved by Guilhermesene4096,

Recommended Posts

Hello dears,

Some of our customers are reporting my website is locket to access form their PCs. The message that appears when they try to access to the url is the following:



But, when I look for more information on the openTip, it seems that all its OK.



Could you guys help me to understand why my webpage is filtered as dangerous?




  • Like 1
Link to comment
Share on other sites

@Cody_MGO Welcome
I have sent your URL to Kaspersky Virus Lab and will provide the verdict when available.
The analysis may take a few hours or days (normally it doesn't take long), so I ask that you please wait.
If it is considered a false positive, it will be removed from detection in the next update of your Kaspersky product.
  • Like 4
Link to comment
Share on other sites

  • Solution


⚠️ Final verdict from Kaspersky Virus Lab



This is not a false alarm. This site is infected.
Here is the malicious code:
{sgAddEvent(window, "sgpbWillOpen", function(e) {if (e.detail.popupId == "258") {var hswj...
If you are a webmaster, please remove the above code from the page. Also we strongly recommend that you change passwords to all services that can be used to modify website contents because they may have been stolen.

Best regards, Xxxxxxx Xxxxxx, Malware Analyst
39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700 http://www.kaspersky.com https://securelist.com
https://opentip.kaspersky.com/ - get insights about suspicious files, hashes, URLs, IP addresses or domain names"

Edited by Guilhermesene4096
  • Like 3
  • Thanks 1
Link to comment
Share on other sites


Reading the posts, Cody_MGO checked the website with Kasperky Intelligent Portal, and it showed everything was fine.

Now you say that it is not a false alarm.

In other words, the "Kaspersky Intelligent Portal" is a useless tool, being there just for fun.


Link to comment
Share on other sites


Kaspersky Intelligent Portal performs an analysis and returns a first result of a file/website scan at first glance.

There are situations where there is a need for a more in-depth analysis of a malicious website and/or file, so we send it to Kaspersky's virus laboratories.

Therefore, KOTIP provides a first opinion, where, if necessary, it is sent back for further analysis to Kaspersky's virus laboratories.

  • Like 1
Link to comment
Share on other sites

Thank you for your prompt message.

I am surprised Kasperky has different opinions on the same item. It sounds like a medical consultation: you see a doctor who says you are healthy and there are no problems, and then another one says you are not so healthy. I know in computing thing work in two ways only: 0 or 1, yes or no. I have a friend who attempted to do banking online about two or three weeks ago. Kasperky told him the website is infected with HEUR: Trojan.Script.Balada.gen. Every day for about two weeks, he tried to log in to that website, and each time he did this, he got the same warning. Now I am asking myself: What do the bank's IT and security staff do?

Don't they realize that something is wrong?

Then he tried a site just for his curiosity and everything was fine. And no, I do not work for these guys, or get any commission.

https:// quttera . com/website-malware-scanner

Again, thank you for your message and I am interested to hear your opinion.

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in

Sign In Now

  • Create New...